Skip to content
Thursday, 8 October 2026
Tenesys AI News
Subscribe
Cyber Security· Important

Talos exposes AI-assisted spear-phishing campaign bypassing Google MFA in real time

In short: Cisco Talos documented a threat actor tracked as UAT-11985 running a spear-phishing campaign against Taiwan research organizations, impersonating academic and policy institutions using fabricated event invitations. The emails show patterns consistent with AI-assisted content generation, allowing the actor to rapidly customize lures while keeping a consistent social-engineering structure. The campaign also used quishing (malicious QR codes on altered event posters) and a real-time adversary-in-the-middle (AitM) phishing kit that impersonates Google sign-in pages to intercept credentials and MFA challenges, harvesting full authenticated session tokens. Talos assesses with moderate confidence the phishing kit's interface was originally built in Simplified Chinese before being localized to Traditional Chinese and English.

Source: Cisco TalosCisco TalosOriginal article ↗

This summary was generated automatically by AI from Cisco Talos's publication. It is our own text, not a copy of the original — facts, figures and quotes belong to the source, linked above and below.

What changed?

  • 1Spear-phishing emails impersonate real institutions (Taiwan European Union Centre, NCCU Institute of International Relations, Taiwan Research Institute) with fabricated senders
  • 2Near-identical structure and formulaic, grandiose language across emails suggests reuse of an AI-generated prompt template for personalization at scale
  • 3Malicious QR codes embedded in otherwise legitimate-looking event posters (quishing), targeting people who print/display them
  • 4Phishing kit impersonates Google sign-in across zh-CN, zh-TW, en locales using HTTP POST (data exfiltration) plus WebSocket (real-time C2) to dynamically control MFA challenge screens
  • 5Kit captures complete authenticated session tokens, effectively bypassing MFA protections
  • 6Heavy JavaScript obfuscation using Base64 string arrays and array-rotation shuffle loops to evade static analysis
  • 7Localization architecture and lexical choices indicate the developer's primary language is Simplified Chinese

Why it matters

This shows attackers combining AI-generated social engineering with a real-time MFA-bypassing phishing kit, meaning traditional MFA alone is no longer sufficient protection against well-resourced, targeted phishing — organizations need phishing-resistant authentication and user awareness of both email and physical (QR code) lures.

What it means for AI agents and contact centers

If your company or its staff use Google Workspace accounts for business communication, be aware that MFA codes alone do not stop this type of real-time AitM attack; consider phishing-resistant authentication methods (hardware security keys, FIDO2) and train staff to recognize mismatched hyperlinks and suspicious QR codes on printed materials, since contact-center and back-office staff are common spear-phishing targets.

Sources

  • Cisco TalosOfficialPrimary source
    „UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing“
    8 Oct 2026, 13:01
    Original article →
Published by source
8 Oct 2026, 13:01
Found by our system
8 Oct 2026, 13:08
Summary generated
8 Oct 2026, 13:09

This article was written by AI from the original source. Facts, numbers and prices come from the source; missing values are marked “Not specified”. Legal notice, copyright and privacy

Talos exposes AI-assisted spear-phishing campaign bypassing Google MFA in real time · TENESYS AI NEWS